Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-19113: CWE-400: Uncontrolled Resource Consumption in HashiCorp ConsulCVE-2026-19113
0

HashiCorp Consul versions 1.3.0 through 2.0.2 contain an unauthenticated denial of service vulnerability in several agent HTTP API endpoints. An attacker can cause the agent to consume excessive memory, leading to service disruption. This issue is fixed in Consul 2.0.3 and later versions, including specific enterprise releases.

Join the discussion
CVE-2026-19017: CWE-862: Missing Authorization in HashiCorp ConsulCVE-2026-19017
0

HashiCorp Consul versions 1.18.21 through 2.0.2 have a vulnerability allowing a privileged attacker with operator:write permission to cause partial arbitrary file reads when using the Vault Connect CA provider with JWT or AppRole authentication. This can lead to exfiltration of sensitive credential files from the Consul server host. The issue is fixed in Consul 2.0.3 and later enterprise versions.

Join the discussion
CVE-2026-19016: CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in HashiCorp ConsulCVE-2026-19016
0

HashiCorp Consul versions 1.19.1 through 2.0.2 contain a vulnerability where the {{session:write}} ACL permission is not enforced for session deletion via the transaction API. This allows an authenticated user with network access to the Consul server RPC port to delete arbitrary sessions without proper authorization. The issue is fixed in Consul 2.0.3 and specified Enterprise versions.

Join the discussion
CVE-2026-19015: CWE-770: Allocation of Resources Without Limits or Throttling in HashiCorp ConsulCVE-2026-19015
0

HashiCorp Consul versions 1.2.0 through 2.0.2 contain a vulnerability in the Connect CA roots endpoint that allows uncontrolled resource consumption by growing the agent's Connect CA roots cache without limits. This issue bypasses the operator's cache-disable configuration. The vulnerability is fixed in Consul 2.0.3 and specific enterprise versions.

Join the discussion
CVE-2026-19014: CWE-770: Allocation of Resources Without Limits or Throttling in HashiCorp ConsulCVE-2026-19014
0

HashiCorp Consul versions 1.17.0 through 2.0.2 contain a resource consumption vulnerability in the Connect authorization endpoint. This flaw allows an attacker to cause uncontrolled growth of the agent's intention-match cache, bypassing the operator's cache-disable settings. The issue is addressed in Consul 2.0.3 and later versions, including specific Enterprise releases.

Join the discussion
CVE-2026-19012: CWE-476: NULL Pointer Dereference in HashiCorp ConsulCVE-2026-19012
0

HashiCorp Consul versions 1.18.0 through 2.0.2 contain a vulnerability (CVE-2026-19012) where an authenticated user with config-entry write permission can cause a denial of service by submitting a crafted service-router configuration entry that crashes the Consul server. This issue affects both the Community and Enterprise editions and is fixed in versions 2.0.3 and later.

Join the discussion
CVE-2026-15972: CWE-770: Allocation of Resources Without Limits or Throttling in HashiCorp ConsulCVE-2026-15972
0

HashiCorp Consul versions 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service attack via unbounded connection acceptance on external gRPC listeners. An attacker can exhaust system resources such as file descriptors, goroutines, and memory by opening many incomplete connections, potentially disrupting legitimate client connections. This vulnerability is fixed in Consul 2.0.3 and later versions, including specific enterprise releases.

Join the discussion
CVE-2026-15970: CWE-647: Non-Canonical URL Authorization in HashiCorp ConsulCVE-2026-15970
0

HashiCorp Consul versions 1.20.1 through 2.0.2 contain a vulnerability (CVE-2026-15970) that allows an authenticated mesh workload to bypass path-based deny intentions when a service proxy is configured with a custom public listener. This issue is fixed in Consul 2.0.3 and specific Enterprise versions.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:github/Consul
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses